MeusClub

MeusClub Legal

MeusClub Privacy Notice

Last updated: 12 July 2026

This Notice describes how personal data is processed in the MeusClub app, on meusclub.com and in connected services. Language versions are intended to be equivalent; mandatory legal rights always remain applicable.

1. Controller and contact details

The controller is Tenpaso Ltd, a company registered in Malta under number C 116371, with registered office at SOHO St. Julians, Punchbowl Centre, Unit P033, Triq Elija Zammit, San Giljan STJ 3154, Malta.

For privacy, personal data, illegal-content and Digital Services Act requests, contact privacy@meusclub.com. For general support, contact support@meusclub.com. Tenpaso Ltd has not appointed a data protection officer because, as at the date of this Notice, it does not consider the mandatory conditions in Article 37 GDPR to apply; this assessment is reviewed when activities or risks change.

2. Scope and roles of MeusClub and Clubs

Tenpaso Ltd acts as controller for accounts, platform security, MeusClub features, the technical wallet, community, support, privacy choices and its own compliance. Clubs may act as separate controllers for venue management, memberships, sports services, administrative duties and their own communications; in some workflows Tenpaso processes data on a Club's behalf under a data processing agreement. The actual role depends on the activity performed, not only on contractual labels.

When you interact with a Club, its contact details and notices may supplement this Notice for processing performed directly by that Club.

3. Categories of data processed

Depending on the features used, we process: identity and contact details, credentials and login providers, phone number, country, language, age declaration, profile and avatar; Clubs, sports, level, availability, results and statistics; bookings, events, memberships, wallet, amounts, transactions and payment status; posts, Moments, comments, reactions, chats, audio, photos, videos, attachments, reports and moderation decisions; support tickets and communications; push tokens, IP address, user agent, session, security logs, app version, operating system, errors and diagnostics.

For wellness features we may process, only after your explicit consent, weight and an optional indicator used for estimation, together with estimated calories, distance and duration derived from matches. Although they are not clinical measurements, those data and outputs may reveal information about physical condition; we therefore treat them conservatively as health data where Article 9 GDPR applies. For AI features we process prompts and the minimized context described in the dedicated section. We also retain evidence of Terms acceptance, acknowledgement of notices, notices displayed and privacy choices.

4. Special-category data and freely entered content

We do not request diagnoses or medical records. Wellness processing is separate, optional and off by default; it is not used for diagnosis or health decisions. Please do not enter additional special-category personal data, identity documents or unnecessary third-party data in chats, posts, AI prompts or tickets.

If such data is entered voluntarily, we process it only as necessary to provide the feature, protect users and the platform, handle a report or comply with law.

5. Sources of data

We receive data from you; from the device when you activate a feature or permission; from Clubs with which you interact; from other users; from Google or Apple login providers; from Stripe for top-up outcomes and metadata; from operating systems and push providers; and from technical providers reporting delivery, errors, fraud or security.

We do not buy personal-data lists and do not access the device address book.

6. Purposes and legal bases

We use data to create and protect the account; provide profiles, bookings, events, community, chat, media, wallet, top-ups, support and requested AI features; manage relationships with Clubs; send operational communications; prevent fraud, abuse and incidents; moderate content and handle complaints; establish, exercise or defend claims; and meet legal, tax, accounting, consumer and DSA duties.

Depending on the processing, the legal basis is: performance of a contract or pre-contractual steps; legal obligation; legitimate interests in security, availability, abuse prevention, legal defence and strictly necessary improvement; consent for marketing and non-essential analytics; and the user's explicit choice to connect Klipy. Wellness processing and any inclusion of its context in AI Coach rely on two separate explicit consents under Articles 6(1)(a) and 9(2)(a) GDPR. Where processing is required for the requested service, acknowledging the Privacy Notice is not consent.

7. Required data, optional data and privacy choices

Email, phone, minimum profile details, role, age declaration and data required by a requested feature are mandatory. Profile photos, social content, wellness, marketing, non-essential analytics and the Klipy GIF connection are optional.

Analytics, marketing, Klipy, wellness and wellness in AI context are off by default. You can change them in Settings, Privacy choices. Contextual sponsor content described in Section 14 is instead enabled under legitimate interests; in the same panel you can object and switch it off without losing service features. Refusing does not prevent accounts, bookings, wallet, text community, support or AI Coach without wellness. If you withdraw wellness consent, we stop new calculations, automatically disable the linked AI consent and delete saved weight and estimation indicator; the underlying match history remains processed for its separate purposes. You may withdraw only the AI consent while retaining wellness statistics. Withdrawal applies for the future; we retain a minimal record of the choice for accountability.

8. Wallet, top-ups and Stripe payments

In the active product, sports services are paid through the Club wallet. You may fund it through a card top-up processed by Stripe or through a cash amount recorded by the Club. Stripe receives the data required to process a top-up; MeusClub receives identifiers, amount, currency, status and reconciliation data, but does not retain the full card number or CVC.

Ordinary refunds for bookings or services are credited to the wallet under the applicable rules. Technical reversals, disputes, chargebacks or corrections to a card top-up may require communications and adjustments with Stripe and to the balance. Accounting and evidence data may be retained as required by law.

9. Community, chat, media and moderation

Posts, comments, profiles and public or Club content are visible to the recipients indicated by the feature. Chats are visible to participants and, only where necessary and authorised, to personnel responsible for security, support or moderation. We do not perform generalized, proactive AI scanning of private chats.

Reports, reported content, relevant metadata, actions and complaints may be processed for safety, community rules and DSA duties. We may retain a limited copy of disputed material after removal where necessary for evidence, authorities or legal defence.

10. AI Coach and AI Assistant

When you choose to use an AI feature, we send OpenAI your prompt and a server-reconstructed context limited to what is needed for the answer. For AI Coach, context may include match statistics, aggregated booking and payment data and playing patterns; it includes wellness estimates and related inputs only while both wellness consent and the separate AI-context consent are active. Partner and opponent names and identifiers are removed. For the Club AI Assistant, context is operational and aggregated and does not intentionally contain individual player names or contact details.

The request is configured without voluntary provider-side content storage by MeusClub, and we do not use prompts or answers to train proprietary models. OpenAI may apply temporary security and abuse controls under its terms. AI is clearly identified, is read-only, may make mistakes and does not make decisions producing legal or similarly significant effects.

As a rule, MeusClub does not retain AI conversation text in its application audit. If you choose “Report response”, however, we retain as a moderation case the flagged response excerpt only (up to 4,000 characters), the AI feature, category, any details, language, technical message identifier, minimal metadata and the reporting account. The full conversation and prompt are not attached automatically. We use these data for human review, safety, complaint handling and filter improvement under legitimate interests; the outcome remains with authorised personnel.

11. GIF search and display through Klipy

The GIF feature is optional and remains off until you enable it. When you search for a GIF, the term entered is sent by the MeusClub server to Klipy. When you view results or GIF messages, the device requests media from Klipy infrastructure, which may receive the IP address, date and time, requested URL, user agent and other technical data.

For MeusClub partner API traffic, Klipy acts as processor under the DPA incorporated into the applicable terms and processes data to provide, secure, support, maintain and improve the service. Klipy's Ads product is separate and disabled for the MeusClub key/configuration: we send neither advertising identifiers nor your account key, and this traffic is not used for advertising or cross-company tracking. Klipy's notice is available at klipy.com/support/privacy-policy. You can disable the choice at any time; Klipy media are not loaded afterwards.

12. Location and device permissions

If you choose nearby-Club search, the app may request location while in use. In the current version, coordinates remain in temporary device memory to sort or present results and are not sent to or stored in the MeusClub backend. Any future off-device transmission will require code, Notice and store declarations to be updated before activation.

Camera, gallery and microphone are used only when you choose to capture or attach media; notifications require the relevant permission. You can revoke permissions in the operating system, which may make the individual feature unavailable.

13. Analytics, errors and diagnostics

Product telemetry, including navigation events, funnels, performance and UI-quality events, is off until you enable Product analytics. Withdrawal stops new optional events and clears those not yet sent.

Under legitimate interests, we process a limited set of errors strictly necessary for security and availability. Sentry receives errors subject to personal-data scrubbing rules; automatic screenshots and performance tracing are disabled. We do not read IDFA, Android Advertising ID or other advertising identifiers.

14. Communications and marketing

We send email, in-app or push communications needed for login, security, bookings, wallet, Clubs, tickets, legal changes and other requested features. These service communications do not depend on the marketing choice.

We send promotional communications only where there is a valid basis, normally consent. You can withdraw it in Privacy choices or through the mechanism in the communication.

The app can also show sponsored content selected by MeusClub, such as a sponsor screen when opening a feature. Selection is contextual only — placement, country and chosen sport — never based on behavioural profiles or advertising identifiers, and no third-party advertising network is involved. To run these spaces and cap how often they appear, we record, linked to your account, which sponsored content was shown (placement, time, duration) and any tap on it, based on our legitimate interest in funding the service through measured, non-profiled sponsorships. Sponsors only receive aggregate statistics, never your identity or contact details. Sponsored campaigns may be inactive at any given time; this mechanism is described because it can be enabled without an app update. You can object by switching off “Contextual sponsor content” in Settings, Privacy choices, or by writing to privacy@meusclub.com; switching it off stops sponsors and new account-linked records without blocking core features.

15. Recipients and providers

We share data only as necessary with: Supabase for authentication, database, realtime and server functions; Cloudflare R2 for media; Stripe for top-ups, reconciliation and Club Connect; OpenAI for requested AI features; Klipy for optional GIFs; Sentry for errors; Resend for email; Expo, FCM and APNs for notifications and mobile infrastructure; Vercel for web and support surfaces; Google and Apple for login; Clubs, authorised staff, recipient users, professional advisers, authorities and parties to a dispute.

Providers may act as processors, sub-processors or separate controllers depending on the feature. We assess access, contracts and minimisation and update the inventory when a provider changes.

16. International transfers

Some recipients may process data outside the European Economic Area. Depending on the case, we use adequacy decisions, the EU-US Data Privacy Framework for covered entities and processing, Standard Contractual Clauses and supplementary measures. You may request information about the applicable mechanism at privacy@meusclub.com.

17. Retention

Accounts and profiles are retained for the account's life and normally deleted or anonymised within 30 days after closure, subject to duties or disputes. One-to-one private chats currently expire 7 days after the last message; Club chats and community content remain until removal, closure or anonymisation compatible with other users' rights. Media remain until removal or closure, subject to complaints.

Raw crash data are normally retained for up to 90 days; security, audit, moderation and complaint logs — including flagged AI-response excerpts — for up to 24 months after case closure according to criticality; backups normally rotate within 30 days. Sponsor impressions and taps remain linked to the account for no more than 90 days; the user link is then removed and only counts no longer associated with the account may remain. Wellness weight and estimation indicator are retained until consent withdrawal, preference deletion or account closure; on withdrawal they are deleted from the active dataset and no new wellness estimates are generated. Acceptance and choice evidence is retained for the account and normally up to 24 months afterwards. Tax and accounting data may be kept for up to 10 years or another period required by law. Longer retention requires law, litigation, fraud, incident or valid order.

18. Security and personal data breaches

We use access and role controls, encryption in transit, database protections, environment separation, logging, backups, minimisation and incident-response procedures. No system is risk-free, and you should protect your credentials and device.

We document breaches, notify the competent authority within 72 hours where Article 33 GDPR requires it, and inform affected individuals where the high-risk threshold in Article 34 is met.

19. Your rights

You may request access, correction, erasure, restriction, portability, objection to processing based on legitimate interests and withdrawal of consent. You also have the right not to be subject to significant solely automated decisions; MeusClub does not currently make them.

Contact privacy@meusclub.com or use Settings, Account and security, Delete account. You may also use meusclub.com/account-deletion. We may request proportionate information to verify identity. Withdrawal does not affect prior lawfulness.

20. Children

MeusClub is intended for people aged at least 16 in Italy and Malta, even where local law may allow lower ages for specific digital consents. A person aged 16 or 17 declares that they use the service with parental or guardian permission and supervision where required. We may request proportionate evidence if concrete doubts arise.

If we learn that a user does not meet the threshold or lacks necessary authorisation, we may restrict the account, request clarification and delete relevant data.

21. Complaints and authorities

You may complain to the Malta Information and Data Protection Commissioner at idpc.org.mt. If you live in Italy, you may also contact the Garante per la protezione dei dati personali at garanteprivacy.it; you may contact the authority where you live, work or where an alleged infringement occurred.

For illegal-content or moderation complaints, contact privacy@meusclub.com and identify the content, reason and information sufficient to assess it.

22. Changes and final contacts

We may update this Notice for legal, product or provider changes. We will show the new date and, for material changes, provide appropriate notice and renew choices where required. Incompatible new purposes will not be introduced retroactively without a valid basis.

Contacts: privacy and DSA privacy@meusclub.com; support support@meusclub.com; Tenpaso Ltd, C 116371, SOHO St. Julians, Punchbowl Centre, Unit P033, Triq Elija Zammit, San Giljan STJ 3154, Malta; website meusclub.com.